CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15114 | CVE-2005-3910 | Candidate | merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability. | Assigned (20051130) | None (candidate not yet proposed) | View | |
80650 | CVE-2015-3373 | Candidate | The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL. | Assigned (20150421) | None (candidate not yet proposed) | View | |
15370 | CVE-2005-4166 | Candidate | Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter. | Assigned (20051211) | None (candidate not yet proposed) | View | |
80906 | CVE-2015-3629 | Candidate | Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container. | Assigned (20150501) | None (candidate not yet proposed) | View | |
15626 | CVE-2005-4422 | Candidate | Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums. | Assigned (20051220) | None (candidate not yet proposed) | View |
Page 829 of 20943, showing 5 records out of 104715 total, starting on record 4141, ending on 4145